Skip to content

Managing User Group Roles

Grants or removes role-and-scope pairs on a user group, the same pairs the group's permissions table holds. Since anyone who belongs to a group takes their security from the group, this is the op to reach for when the people affected are managed in groups rather than one at a time. Managing User Roles covers the individually managed case, and it has no effect on someone who is in a group.

The op edits the group record and nothing else. Read the next section before you build a rule on it.

what you picked Roles: role A, role B Projects: proj 1, proj 2 Assign or Unassign on the group record the group record changes at once members keep the permissions they had until recalculated

The change does not reach the members on its own

Every person carries a worked-out copy of their permissions, rebuilt from the groups they belong to whenever their own record is written. Permission checks read that copy, not the group.

This op updates the group record and stops there. The members' copies are left alone, so the people in the group keep whatever they had. The op does drop the installation's permission caches on its way out, which makes the next few permission checks slower but changes nothing about the answers they give, since the copies they re-read are the stale ones.

Open the group in the user group screen and save it and every member is recalculated in batches. That is why the change appears to work when you do it by hand and appears to do nothing when a rule does it.

Two ways to finish the job from a rule: save each member afterwards, or treat this op as a way to prepare a group whose membership is assigned later, since taking someone into the group recalculates them.

Fields

Action

Assign or Unassign. A new op arrives set to Assign, and the form will not let you clear it.

Assign adds to what the group already grants and does nothing when the pair is already there. Unassign removes only the pairs you list, and a role left with no scopes drops out of the group record altogether. There is no replace: put an Unassign op in front of an Assign op when you mean to swap a set.

A hand-edited rule with any other word here runs, rewrites the group record unchanged and reports success.

User Group

Which group to change. One group per op, picked from the list of existing groups.

This picker holds nothing but real groups. It does not offer variables and it does not accept text you type, so the group cannot come from the stash. A rule that has to decide the group while it runs needs one op per group behind an IF var condition THEN branch.

A group that no longer exists, in a rule written before it was deleted, stops the op.

Projects

The scopes the roles apply to. The picker takes several entries and lists the project-like resources in your installation, meaning projects and the groups that hold them. Scope explains what qualifies.

The list also offers the variables you declared as a project-like resource, shown as variable: ${name}. A variable declared to hold plain text or a list does not appear here at all. Entries are used as they are, and this is where the op differs from its per-user counterpart. A variable holding a single resource id is fine. A variable holding a list of ids is not unpacked into entries, and it stops the op with an error rather than assigning anything. Pick the scopes directly, one entry each.

Typing all as an entry is honoured: the roles are applied across every project-like resource in the installation. Unassign with all clears the role from the group everywhere, in one op and with no confirmation.

Entries that are not project-like resources are dropped without a word, so a stale id produces no error and no grant. A comma-separated string is treated as one entry and lands in that same bin, so proj_foo,proj_bar typed as a single entry grants nothing.

Roles

Which roles to grant or remove. The picker takes several and lists every role defined under Roles, plus the variables you declared as holding a value or a list.

Roles are matched by id, and an id that matches nothing is skipped in silence. The same restriction as Projects applies, but without the error: a variable holding a list of role ids is not unpacked, so it matches nothing and the op finishes having changed nothing at all. Pick the roles themselves.

Every role is applied to every scope. Three roles across four scopes is twelve pairs in one op.

What comes back

With a Return Key set, you get the group's record after the change, including its mid, its name and its project_security. That last one is a list rather than a tree: one entry per role-and-scope pair, each naming the role, the scope and what kind of scope it is. Reading it back is the way to confirm the op did what you asked, since the members tell you nothing.

Without a Return Key the change still happens and the record is discarded.

Failure and rollback

A group that cannot be found stops the op, as does a hand-edited rule missing the action, the group, the roles or the projects entry. A list variable in Projects stops it too. Everything else on this page fails quietly. The op's Error Handling setting decides whether a stop ends the rule.

There is no undo. Build one from a mirrored op with the opposite Action, and untick Run Forward on it so it only runs on the way back. Untick Run Rollback on the forward op as well, or it applies the same change again during a rollback pass and cancels the mirror.

Combining with other ops

Guard it with IF var condition THEN so a workflow rule only changes group permissions at the point a request is approved, rather than on every save of the topic.

Reach for Managing User Roles instead when the people involved are not in any group. Use Load User to find out which case you are in: its groups entry is empty for an individually managed person.

Tell people what changed with Send a notification, and say when it takes effect if the members still need recalculating.

Examples

Open up a new project to an existing group once its setup topic is approved.

Action       Assign
User Group   qa-team
Projects     proj_foo
Roles        tester

Take a role away from a group across everything it covers.

Action       Unassign
User Group   contractors
Projects     all
Roles        developer

Swap a role for a narrower one, as two ops in a row.

Action       Unassign
User Group   qa-team
Projects     proj_foo
Roles        approver

Action       Assign
User Group   qa-team
Projects     proj_foo
Roles        reviewer